CVE-2024-9431
- EPSS 0.61%
- Veröffentlicht 20.03.2025 10:09:46
- Zuletzt bearbeitet 15.10.2025 13:15:59
In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After logging into the system, users can change the passwords of other users, leading to potential account takeover.
CVE-2024-10267
- EPSS 0.61%
- Veröffentlicht 20.03.2025 10:09:43
- Zuletzt bearbeitet 18.07.2025 19:57:36
An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and passwords, by attempting to register a new account with an email that i...
CVE-2024-9418
- EPSS 0.59%
- Veröffentlicht 20.03.2025 10:09:21
- Zuletzt bearbeitet 15.10.2025 13:15:59
In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in plaintext. This vulnerability allows an attacker to retrieve the password of another user, leading to potential account takeover.
CVE-2024-9415
- EPSS 1.47%
- Veröffentlicht 20.03.2025 10:09:06
- Zuletzt bearbeitet 29.07.2025 19:18:58
A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. This vulnerability allows an attacker to upload an arbitrary file to the server, potentially leading to remote code execution or ove...
CVE-2024-21552
- EPSS 0.63%
- Veröffentlicht 22.07.2024 15:15:02
- Zuletzt bearbeitet 15.04.2026 00:35:42
All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI application server...
CVE-2023-48055
- EPSS 0.37%
- Veröffentlicht 16.11.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:03
SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the disclosure of information and communications.